# Matt Blaze

> 1963– · Computer Scientist, Cryptographer
>
> **Recorded contribution:** Cryptography research; Clipper chip analysis; security research

## How to use this dossier

Read for a causal chain, not a hero story: inherited problem → contribution → mechanism → downstream capability → limit. Then close the page and complete the reconstruction exercise from memory.

## 1. Historical orientation

Matt Blaze has researched cryptographic systems, lawful interception, voting, and communications security. His 1994 analysis of the U.S. Clipper key-escrow system found a protocol weakness in its Law Enforcement Access Field, demonstrating that exceptional-access mechanisms create new technical claims attackers can contest. This work makes a security claim depend on an explicit adversary model, mathematical construction, key or randomness discipline, and a testable notion of success. The chronology is used causally: it connects the inherited constraint to an implementable mechanism and then to later reuse, instead of treating fame, job title, or eventual market success as the explanation.

## 2. The problem inherited

Policy proposals wanted strong civilian encryption combined with government recovery, but any escrow signaling, key custody, and access path also expanded the attack and failure surface. Secrecy, integrity, authenticity, privacy, and consensus cannot be delivered by obscurity. The protected asset and attacker capabilities must be stated before an algorithm can be judged.

## 3. The central contribution

Clipper attached an escrow-related field to encrypted traffic; Blaze showed a transmitter could manipulate the field so ordinary communication succeeded while escrow recovery information became invalid. The contribution is best understood as a construction plus its assumptions and proof target, not as a magic shield around data.

## 4. Reconstruct the mechanism

1. Write every party, device key, escrow key, message field, and validation step in the exceptional-access protocol. Define the parties, keys or randomness, messages, and exact security property.
2. Trace normal encryption and authorized recovery without assuming hidden fields are honest. Execute setup and the core transform on a toy instance small enough to inspect.
3. Let a malicious endpoint alter or omit the access field while preserving the recipient’s decryption path. Give the receiver or verifier only the information the construction permits and check the intended result.
4. Add validation and then identify its interoperability, denial, key-theft, insider, and global-governance costs. Strengthen the attacker, weaken randomness, reuse state, or change a hardness assumption and identify the resulting break.

## 5. What changed downstream

- The analysis became a canonical example of adversarial review of mandated access and informed continuing debates over encryption backdoors.
- The work supplied later protocols with a composable primitive or a sharper way to state what an attacker should be unable to do.
- The transferable first-principles lesson is to separate the artifact named in “Cryptography research; Clipper chip analysis; security research” from the mechanism, surrounding institution, and evidence that allowed later systems to depend on it.

## 6. Attribution, limits, and uncertainty

- Blaze identified an important flaw but was one participant in a broad Clipper debate involving researchers, civil society, agencies, vendors, and policymakers. One broken design does not by itself prove every imaginable access proposal impossible, though it supplies concrete burden of proof.
- Mathematical security does not automatically secure implementations, endpoints, key custody, incentives, or institutions.
- The subject is living or the registry has no death year; current titles and institutional affiliations are treated as dated snapshots verified on 2026-08-09, not permanent identity claims.

## 7. Reconstruction lab

Design a fictional escrowed-messaging packet and attack it as endpoint, escrow insider, and network adversary. For every repair, add the new trusted party and failure mode to a ledger. Separate the toy mathematics from production security; finish with an attack caused by violating one stated assumption.

## 8. Evidence trail

- [Protocol Failure in the Escrowed Encryption Standard](https://www.mattblaze.org/papers/eesproto.pdf) — Matt Blaze
- [Matt Blaze](https://en.wikipedia.org/wiki/Matt_Blaze) — Wikipedia contributors · overview and bibliography
- [Matt Blaze structured identity record](https://www.wikidata.org/wiki/Q5954621) — Wikidata contributors · CC0

---

*Research checked 2026-08-09. Dates, roles, and claims about living people are historical snapshots. Linked sources remain the authority; this dossier is original instructional synthesis.*
